Windows Analysis Report
fdm_x64_setup.exe

Overview

General Information

Sample Name: fdm_x64_setup.exe
Analysis ID: 690704
MD5: 31dd1d05a00ad4c3cbb94a8af6726f98
SHA1: f8a33287bef3e721d52f6b8152822bbdc9a9c3a8
SHA256: 072ee364c81db95d8f45c8d06037cba332cd004d3b8290ee435b369f7becb829
Infos:

Detection

Score: 24
Range: 0 - 100
Whitelisted: false
Confidence: 80%

Signatures

Obfuscated command line found
Uses schtasks.exe or at.exe to add and modify task schedules
Uses 32bit PE files
PE file contains strange resources
Drops PE files
PE file contains sections with non-standard names
Found dropped PE file which has not been started or loaded

Classification

Source: fdm_x64_setup.exe Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, BYTES_REVERSED_LO, 32BIT_MACHINE, BYTES_REVERSED_HI
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\unins000.dat
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-7CO7S.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-D0NHS.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-R31M0.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-V105V.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-1LRU2.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-99UVP.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-8QFML.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-OVIG9.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-H4KKL.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-B4BVM.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-90813.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-VG0RE.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-9G3VC.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-6EUK9.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-EA331.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-I4TC5.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-BHSLV.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-5PCKA.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-5L5E8.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-3PMR7.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-940K7.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-RPNAI.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-4IDOF.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-GGULB.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-ONUPS.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-3V1LO.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-242RF.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-87ER9.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-GMHAL.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-7H68L.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-5S1KV.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-7CG1Q.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-8OREA.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-4DDA0.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-0BB6O.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-VEVHM.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-AA7GK.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-RG2KI.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-8IIMH.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-OFL7K.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-U351B.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-JRBN3.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-23BE3.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-T89KD.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-FD6K5.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-8ATK9.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-N2MR5.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-BNRSO.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-4000T.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-T4J2V.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-PSIFG.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-B3NPD.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-G7439.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-2M2DR.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-9O60R.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-GTRN5.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-N12R1.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-JFJJL.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-TTH8V.tmp
Source: fdm_x64_setup.exe Static PE information: certificate valid
Source: fdm_x64_setup.exe Static PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown DNS traffic detected: queries for: accounts.google.com
Source: fdm_x64_setup.exe Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, BYTES_REVERSED_LO, 32BIT_MACHINE, BYTES_REVERSED_HI
Source: fdm_x64_setup.exe Static PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
Source: fdm_x64_setup.exe Static PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
Source: C:\Users\alfredo\Desktop\fdm_x64_setup.exe File read: C:\Users\alfredo\Desktop\fdm_x64_setup.exe
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Key opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Key opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales
Source: C:\Users\alfredo\Desktop\fdm_x64_setup.exe Key opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales
Source: C:\Users\alfredo\Desktop\fdm_x64_setup.exe Key opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales
Source: unknown Process created: C:\Users\alfredo\Desktop\fdm_x64_setup.exe "C:\Users\alfredo\Desktop\fdm_x64_setup.exe"
Source: C:\Users\alfredo\Desktop\fdm_x64_setup.exe Process created: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp "C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp" /SL5="$2038C,34713263,780288,C:\Users\alfredo\Desktop\fdm_x64_setup.exe"
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Process created: C:\Windows\System32\schtasks.exe "schtasks.exe" /end /tn FreeDownloadManagerHelperService
Source: C:\Windows\System32\schtasks.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Process created: C:\Windows\System32\schtasks.exe "schtasks.exe" /end /tn FreeDownloadManagerHelperService
Source: C:\Users\alfredo\Desktop\fdm_x64_setup.exe Process created: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp "C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp" /SL5="$2038C,34713263,780288,C:\Users\alfredo\Desktop\fdm_x64_setup.exe"
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{00BB2765-6A77-11D0-A535-00C04FD7D062}\InProcServer32
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:2520:120:WilError_02
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:2520:304:WilStaging_02
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp File created: C:\Program Files\Softdeluxe
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp File created: C:\Users\alfredo\AppData\Local\Programs
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp File created: C:\Users\alfredo\AppData\Local\Temp\is-IHEBO.tmp
Source: classification engine Classification label: sus24.winEXE@6/26@3/0
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Key value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion RegisteredOrganization
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Key value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion RegisteredOwner
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Window found: window name: TMainForm
Source: Window Recorder Window detected: More than 3 window changes detected
Source: fdm_x64_setup.exe Static file information: File size 35460872 > 1048576
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\unins000.dat
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-7CO7S.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-D0NHS.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-R31M0.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-V105V.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-1LRU2.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-99UVP.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-8QFML.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-OVIG9.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-H4KKL.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-B4BVM.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-90813.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-VG0RE.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-9G3VC.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-6EUK9.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-EA331.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-I4TC5.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-BHSLV.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-5PCKA.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-5L5E8.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-3PMR7.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-940K7.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-RPNAI.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-4IDOF.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-GGULB.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-ONUPS.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-3V1LO.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-242RF.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-87ER9.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-GMHAL.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-7H68L.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-5S1KV.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-7CG1Q.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-8OREA.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-4DDA0.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-0BB6O.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-VEVHM.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-AA7GK.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-RG2KI.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-8IIMH.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-OFL7K.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-U351B.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-JRBN3.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-23BE3.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-T89KD.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-FD6K5.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-8ATK9.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-N2MR5.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-BNRSO.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-4000T.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-T4J2V.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-PSIFG.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-B3NPD.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-G7439.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-2M2DR.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-9O60R.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-GTRN5.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-N12R1.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-JFJJL.tmp
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Directory created: C:\Program Files\Softdeluxe\Free Download Manager\is-TTH8V.tmp
Source: fdm_x64_setup.exe Static PE information: certificate valid
Source: fdm_x64_setup.exe Static PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE

Data Obfuscation

barindex
Source: C:\Users\alfredo\Desktop\fdm_x64_setup.exe Process created: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp "C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp" /SL5="$2038C,34713263,780288,C:\Users\alfredo\Desktop\fdm_x64_setup.exe"
Source: C:\Users\alfredo\Desktop\fdm_x64_setup.exe Process created: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp "C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp" /SL5="$2038C,34713263,780288,C:\Users\alfredo\Desktop\fdm_x64_setup.exe"
Source: fdm_x64_setup.exe Static PE information: section name: .didata
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp File created: C:\Program Files\Softdeluxe\Free Download Manager\is-2M2DR.tmp Jump to dropped file
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp File created: C:\Program Files\Softdeluxe\Free Download Manager\api-ms-win-crt-locale-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp File created: C:\Program Files\Softdeluxe\Free Download Manager\is-RG2KI.tmp Jump to dropped file
Source: C:\Users\alfredo\Desktop\fdm_x64_setup.exe File created: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Jump to dropped file
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp File created: C:\Program Files\Softdeluxe\Free Download Manager\is-AA7GK.tmp Jump to dropped file
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp File created: C:\Program Files\Softdeluxe\Free Download Manager\is-VEVHM.tmp Jump to dropped file
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp File created: C:\Program Files\Softdeluxe\Free Download Manager\ffmpeg.exe (copy) Jump to dropped file
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp File created: C:\Program Files\Softdeluxe\Free Download Manager\api-ms-win-crt-stdio-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp File created: C:\Program Files\Softdeluxe\Free Download Manager\is-G7439.tmp Jump to dropped file
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp File created: C:\Program Files\Softdeluxe\Free Download Manager\importwizard.exe (copy) Jump to dropped file
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp File created: C:\Program Files\Softdeluxe\Free Download Manager\is-9O60R.tmp Jump to dropped file
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp File created: C:\Program Files\Softdeluxe\Free Download Manager\is-B3NPD.tmp Jump to dropped file
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp File created: C:\Program Files\Softdeluxe\Free Download Manager\api-ms-win-crt-runtime-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp File created: C:\Program Files\Softdeluxe\Free Download Manager\is-0BB6O.tmp Jump to dropped file
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp File created: C:\Program Files\Softdeluxe\Free Download Manager\api-ms-win-crt-math-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp File created: C:\Program Files\Softdeluxe\Free Download Manager\api-ms-win-crt-multibyte-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp File created: C:\Program Files\Softdeluxe\Free Download Manager\libEGL.dll (copy) Jump to dropped file
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp File created: C:\Program Files\Softdeluxe\Free Download Manager\is-GTRN5.tmp Jump to dropped file
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp File created: C:\Program Files\Softdeluxe\Free Download Manager\is-7CG1Q.tmp Jump to dropped file
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp File created: C:\Program Files\Softdeluxe\Free Download Manager\api-ms-win-crt-process-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp File created: C:\Program Files\Softdeluxe\Free Download Manager\is-4DDA0.tmp Jump to dropped file
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp File created: C:\Program Files\Softdeluxe\Free Download Manager\helperservice.exe (copy) Jump to dropped file
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp File created: C:\Users\alfredo\AppData\Local\Temp\is-IHEBO.tmp\_isetup\_setup64.tmp Jump to dropped file
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp File created: C:\Program Files\Softdeluxe\Free Download Manager\is-8OREA.tmp Jump to dropped file
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp File created: C:\Program Files\Softdeluxe\Free Download Manager\libcrypto-1_1-x64.dll (copy) Jump to dropped file
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp File created: C:\Program Files\Softdeluxe\Free Download Manager\api-ms-win-crt-private-l1-1-0.dll (copy) Jump to dropped file

Boot Survival

barindex
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Process created: C:\Windows\System32\schtasks.exe "schtasks.exe" /end /tn FreeDownloadManagerHelperService
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\alfredo\Desktop\fdm_x64_setup.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Dropped PE file which has not been started: C:\Program Files\Softdeluxe\Free Download Manager\is-2M2DR.tmp Jump to dropped file
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Dropped PE file which has not been started: C:\Program Files\Softdeluxe\Free Download Manager\api-ms-win-crt-locale-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Dropped PE file which has not been started: C:\Program Files\Softdeluxe\Free Download Manager\is-RG2KI.tmp Jump to dropped file
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Dropped PE file which has not been started: C:\Program Files\Softdeluxe\Free Download Manager\is-AA7GK.tmp Jump to dropped file
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Dropped PE file which has not been started: C:\Program Files\Softdeluxe\Free Download Manager\is-VEVHM.tmp Jump to dropped file
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Dropped PE file which has not been started: C:\Program Files\Softdeluxe\Free Download Manager\ffmpeg.exe (copy) Jump to dropped file
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Dropped PE file which has not been started: C:\Program Files\Softdeluxe\Free Download Manager\api-ms-win-crt-stdio-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Dropped PE file which has not been started: C:\Program Files\Softdeluxe\Free Download Manager\is-G7439.tmp Jump to dropped file
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Dropped PE file which has not been started: C:\Program Files\Softdeluxe\Free Download Manager\importwizard.exe (copy) Jump to dropped file
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Dropped PE file which has not been started: C:\Program Files\Softdeluxe\Free Download Manager\is-9O60R.tmp Jump to dropped file
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Dropped PE file which has not been started: C:\Program Files\Softdeluxe\Free Download Manager\is-B3NPD.tmp Jump to dropped file
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Dropped PE file which has not been started: C:\Program Files\Softdeluxe\Free Download Manager\api-ms-win-crt-runtime-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Dropped PE file which has not been started: C:\Program Files\Softdeluxe\Free Download Manager\is-0BB6O.tmp Jump to dropped file
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Dropped PE file which has not been started: C:\Program Files\Softdeluxe\Free Download Manager\api-ms-win-crt-math-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Dropped PE file which has not been started: C:\Program Files\Softdeluxe\Free Download Manager\api-ms-win-crt-multibyte-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Dropped PE file which has not been started: C:\Program Files\Softdeluxe\Free Download Manager\libEGL.dll (copy) Jump to dropped file
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Dropped PE file which has not been started: C:\Program Files\Softdeluxe\Free Download Manager\is-GTRN5.tmp Jump to dropped file
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Dropped PE file which has not been started: C:\Program Files\Softdeluxe\Free Download Manager\is-7CG1Q.tmp Jump to dropped file
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Dropped PE file which has not been started: C:\Program Files\Softdeluxe\Free Download Manager\api-ms-win-crt-process-l1-1-0.dll (copy) Jump to dropped file
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Dropped PE file which has not been started: C:\Program Files\Softdeluxe\Free Download Manager\is-4DDA0.tmp Jump to dropped file
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Dropped PE file which has not been started: C:\Program Files\Softdeluxe\Free Download Manager\helperservice.exe (copy) Jump to dropped file
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Dropped PE file which has not been started: C:\Users\alfredo\AppData\Local\Temp\is-IHEBO.tmp\_isetup\_setup64.tmp Jump to dropped file
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Dropped PE file which has not been started: C:\Program Files\Softdeluxe\Free Download Manager\is-8OREA.tmp Jump to dropped file
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Dropped PE file which has not been started: C:\Program Files\Softdeluxe\Free Download Manager\libcrypto-1_1-x64.dll (copy) Jump to dropped file
Source: C:\Users\alfredo\AppData\Local\Temp\is-N1RHV.tmp\fdm_x64_setup.tmp Dropped PE file which has not been started: C:\Program Files\Softdeluxe\Free Download Manager\api-ms-win-crt-private-l1-1-0.dll (copy) Jump to dropped file
⊘No contacted IP infos